Secure Infrastructure Control Plane
About Lab Manager
A highly secure, multi-tenant control plane for standing up, scaling, testing, and securing complex lab, demo, and edge environments — hypervisors, networks, identity, and cloud — from a single console.
mTLS authenticated
Multi-tenant
Self-learning scale testing
Self-healing
One-click deployment
Security posture
Highly secure by design
- Mutual-TLS (mTLS) authentication — the console and every managed component authenticate each other with cryptographic certificates, not just shared passwords, so only trusted, verified systems can join.
- Signed & encrypted everywhere — every instruction is cryptographically signed and every secret is encrypted in transit and at rest.
- Automatic intrusion detection — continuously watches for brute-force and forged-credential attempts and flags them in real time with a full audit trail.
- Firewall safeguards that respond automatically — detected offenders are auto-blocked at the network firewall, governed by a unified trusted-IP allow-list and enforced rule-priority model, with safeguards that make it impossible to accidentally lock out trusted addresses.
- Secure credential vault — Azure Key Vault–backed secret storage, escrow, and break-glass recovery, so credentials stay protected and recoverable even in a disaster.
Capabilities
Automated provisioning & elastic scaling
- Auto-provisioning — automatically clones and configures VMs and clients on demand to reach a target size, with safeguards so it only touches what it should.
- VM / client shedding — monitors CPU, memory, and client-count pressure and automatically sheds or halts provisioning when a host is overloaded, then recovers as capacity frees up.
- Golden-image cloning — prepare a system once and spin up any number of identical, self-registering copies for rapid fleet expansion.
- Full VM lifecycle — clone-from-template, snapshots, start/stop, a template library, and in-browser console and shell access.
Intelligent, self-learning scale testing
- Realistic scale testing — generate fleets of simulated clients producing true-to-life network traffic (DHCP, DNS, web, collaboration, NAC onboarding) to load-test and demonstrate the whole environment without physical devices.
- Automatic alert & insight learning — the platform learns the exact client volume and conditions that trigger each network alert or insight, then tunes the simulation to reproduce it on demand and shares those thresholds across tenants.
- Self-building alert/insight catalog — every condition observed anywhere is captured into a shared library, so a test scenario can be built from any alert or insight without staging it first.
Multi-tenancy & delegation
- True multi-tenant isolation — every resource, view, and action is scoped per tenant, so teams or customers only see and touch their own environment.
- Role-based delegation — global admins run the platform; tenant admins safely self-serve their own users, devices, subnets, and directory without platform-wide access.
Identity, directory & Azure integration
- LDAP directory with Azure Entra ID pass-through — a redundant, replicated directory where users authenticate directly against Entra ID, with tenant-scoped user and group management from the console.
- Single sign-on — Entra / OIDC login across the platform and integrated systems.
- Vault-backed credentials — all secrets protected by the secure, recoverable credential vault.
Unified operations & resilience
- One console for everything — hypervisors, firewalls, network access control, IP management, DNS, DHCP, directory, network switches, and certificates in a single pane of glass.
- Automated discovery & sync — discovers devices and keeps IP management, access control, and firewalls in sync with reality.
- Automated certificate management — issues, renews, and distributes TLS certificates to every managed system.
- Zero-touch deployment — add a capability or stand up a backing server with one click; no command line required.
- Always-on & self-healing — self-recovering services with safe, gated updates and automatic rollback, so a bad change can’t take the console down.
- Reporting & monitoring — scheduled per-tenant reports, real-time alerting, live status dashboards, centralized logging, plus automated end-to-end testing and AI-assisted self-repair.